dependabot[bot] opened a new pull request, #44690: URL: https://github.com/apache/superset/pull/44690
Bumps [python-ldap](https://github.com/python-ldap/python-ldap) from 3.4.7 to 3.4.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/python-ldap/python-ldap/releases">python-ldap's releases</a>.</em></p> <blockquote> <h2>3.4.8</h2> <p>Fixes:</p> <ul> <li>Plugged memory and reference leaks at error-handling time (<a href="https://redirect.github.com/python-ldap/python-ldap/issues/40">#40</a>, <a href="https://redirect.github.com/python-ldap/python-ldap/issues/617">#617</a>, <a href="https://redirect.github.com/python-ldap/python-ldap/issues/619">#619</a>, <a href="https://redirect.github.com/python-ldap/python-ldap/issues/620">#620</a>, <a href="https://redirect.github.com/python-ldap/python-ldap/issues/621">#621</a>, <a href="https://redirect.github.com/python-ldap/python-ldap/issues/622">#622</a>, <a href="https://redirect.github.com/python-ldap/python-ldap/issues/632">#632</a>)</li> <li>VLV control now honours contextID passed in (<a href="https://redirect.github.com/python-ldap/python-ldap/issues/618">#618</a>)</li> <li>ldapurl now correctly escapes when emitting a HTML anchor (<a href="https://redirect.github.com/python-ldap/python-ldap/issues/628">#628</a>)</li> <li>_ldap.str2dn now handles empty string correctly (<a href="https://redirect.github.com/python-ldap/python-ldap/issues/549">#549</a>)</li> <li>handle server-sent invalid UTF-8 correctly (by throwing an error) (<a href="https://redirect.github.com/python-ldap/python-ldap/issues/624">#624</a>)</li> <li>corrected ldap.functions export list to remove long gone items</li> </ul> <p>Doc:</p> <ul> <li>fd ownership has now been clarified - if providing an fd to set up a new LDAPObject, it is now owned and managed by the module, do not close it yourself (<a href="https://redirect.github.com/python-ldap/python-ldap/issues/575">#575</a>)</li> <li>clarifications on handling EINTR -> use OPT_RESTART (<a href="https://redirect.github.com/python-ldap/python-ldap/issues/242">#242</a>)</li> <li>clarified build dependencies (<a href="https://redirect.github.com/python-ldap/python-ldap/issues/569">#569</a>)</li> <li>clarified OPT_CLIENT_CONTROLS/OPT_SERVER_CONTROLS (<a href="https://redirect.github.com/python-ldap/python-ldap/issues/639">#639</a>)</li> </ul> <p>Infrastructure:</p> <ul> <li>Build requirement pinned to <code>setuptools>=61</code>: older setuptools ignores the PEP 621 <code>[project]</code> table and produces an sdist with broken metadata (<code>Name: unknown</code>), which made pip silently fall back to ancient releases when building 3.4.5 from source (<a href="https://redirect.github.com/python-ldap/python-ldap/issues/616">#616</a>). Old environments now fail with a clear resolver error instead.</li> <li>Removed the <code>[install]</code> section (<code>compile</code>/<code>optimize</code>) from <code>setup.cfg</code>; it caused <code>bdist_wheel</code> to embed <code>__pycache__</code> byte-code files in published wheels (<a href="https://redirect.github.com/python-ldap/python-ldap/issues/615">#615</a>).</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/python-ldap/python-ldap/blob/main/CHANGES">python-ldap's changelog</a>.</em></p> <blockquote> <p>Released 3.5.0 (unreleased)</p> <p>Breaking:</p> <ul> <li><code>ldap.schema.models.SchemaElement.token_defaults</code> class attribute had to go, we couldn't find a safe way to keep it working with subclasses and are unaware of any users either</li> </ul> <p>API changes:</p> <ul> <li>The deprecated <code>OPT_X_TLS</code> option has been removed, as announced in the 3.4.3 release notes. The <code>OPT_X_TLS_*</code> option constants (such as <code>OPT_X_TLS_NEWCTX</code> and <code>OPT_X_TLS_REQUIRE_CERT</code>) are unaffected.</li> <li>ldap.DummyLock has been removed as it has been useless since Python3.7</li> <li>ldap.controls.KNOWN_RESPONSE_CONTROLS now only contains ResponseControl types</li> <li>Iterating <code>ldap.schema.Entry</code> now correctly iterates over the visible keys, not internal representation</li> <li>code better aligns with documentation: <ul> <li><code>ldap.controls.simple.AuthorizationIdentityResponseControl</code> now decodes returned identity as documented</li> <li><code>LDAPObject</code>'s <code>*_s</code> functions actually return None as advertised</li> <li><code>LDIFParser</code> now correctly ignores unknown url schemes rather than attaching <code>None</code> as value</li> <li>People overriding <code>SyncreplConsumer.syncrepl_present</code> will no longer see <code>SyncDoneControl.refreshDeletes</code> have a value of <code>None</code></li> </ul> </li> <li>If using the search MixIn classes (including SyncreplConsumer) and replacing the relevant controls in <code>KNOWN_RESPONSE_CONTROLS</code> at the same time, make sure you subclass the original implementations</li> <li>Calling <code>ldap.schema.SubSchema.get_structural_oc</code> with incompatible STRUCTURAL object classes has produced undefined behaviour in the past and it does again. This and <code>ldap.schema.{SubSchema,Entry}.attribute_types</code> with DIT content rules enforced will raise an error in future versions</li> </ul> <p>Fixes:</p> <ul> <li><code>ldap.controls.pwdpolicy.PasswordExpiredControl</code> finally returns reported status</li> <li>corrected ldap.functions export list to remove long gone items</li> </ul> <p>Deprecations:</p> <ul> <li>See above note for <code>ldap.schema.SubSchema.get_structural_oc</code> and its users</li> <li><code>ldap.schema.tokenizer.extract_tokens</code> has been replaced with <code>ldap.schema.tokenizer.parse_tokens</code> and will go away eventually</li> <li><code>_ldap</code> module is now a stub forwarding to <code>ldap._ldap</code>, <code>_ldap</code> will go away eventually</li> </ul> <p>Infrastructure:</p> <ul> <li>Building from source now requires setuptools >= 77, needed for the PEP 639 license metadata in <code>pyproject.toml</code></li> <li>Removed the <code>[install]</code> byte-compile options from <code>setup.cfg</code>, so locally built wheels no longer contain <code>__pycache__</code> directories</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/python-ldap/python-ldap/commit/77de2fb34dc640a705a1bd1ca6aed6ba8c8b4050"><code>77de2fb</code></a> Prepare a new release</li> <li><a href="https://github.com/python-ldap/python-ldap/commit/9a87cd0be1382a9ed8f23c1caead53bfc30aa887"><code>9a87cd0</code></a> doc: describe OPT_SERVER_CONTROLS and OPT_CLIENT_CONTROLS</li> <li><a href="https://github.com/python-ldap/python-ldap/commit/af612373d878a5dccddf14cbc1a8d553e5595502"><code>af61237</code></a> test(ldap.controls): test control options against what get_option promises</li> <li><a href="https://github.com/python-ldap/python-ldap/commit/a1859e4709a7bf4c5a4a7ec44b0830b80206a047"><code>a1859e4</code></a> chore: remove not existing names from <code>functions.__all__</code></li> <li><a href="https://github.com/python-ldap/python-ldap/commit/2adb49e84b879ce0b093116887a77584ae0ebd13"><code>2adb49e</code></a> fix(_ldap): Do not leak retoid</li> <li><a href="https://github.com/python-ldap/python-ldap/commit/2bbfd0dd99c299613c26aa9cc2408285ed0b597b"><code>2bbfd0d</code></a> fix(_ldap): do not ignore ldap_parse_result's errors</li> <li><a href="https://github.com/python-ldap/python-ldap/commit/75b9f476470b05a898ea9718ff8a5c542b4a1b7b"><code>75b9f47</code></a> doc: Mention OPT_RESTART for EINTR handling</li> <li><a href="https://github.com/python-ldap/python-ldap/commit/79c8e9954a4c4c55b8119e4f02784664de122fad"><code>79c8e99</code></a> build: stop byte-compiling modules into wheels</li> <li><a href="https://github.com/python-ldap/python-ldap/commit/d9ee3b2f26e1904f8cb4ee48f57ec6194447cdac"><code>d9ee3b2</code></a> build: pin build requirement to setuptools>=61</li> <li><a href="https://github.com/python-ldap/python-ldap/commit/b94dea64bda4a3de824cbb6817693b15fbb966c1"><code>b94dea6</code></a> doc: Correct build dependencies</li> <li>Additional commits viewable in <a href="https://github.com/python-ldap/python-ldap/compare/python-ldap-3.4.7...python-ldap-3.4.8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
